Privacy Notice
This Privacy Notice applies to visitors to www.scottisharchitects.org.uk/
("our website)" or individuals who contact us by telephone, e-mail or other ways, including other electronic means.
1. Who we are
We are Historic Environment Scotland
(HES), an executive non-departmental public body, incorporated and established
under the Historic Environment Scotland Act 2014, being a registered charity
(Scottish Charity number SC045925) and having its principal office at Longmore
House, Salisbury Place, Edinburgh, EH9 1SH.
We are a data controller for
the purposes of the United Kingdom General Data Protection Regulation (UK GDPR)
and Data Protection Act 2018 (DPA 2018).
2. How to contact us
If you have any questions about this Privacy
Notice or our data protection policies generally, please contact us:
By post:
The Data Protection Officer
Historic Environment Scotland
Room G.50
Longmore House
Salisbury Place
Edinburgh, EH9 1SH
By email: dataprotection@hes.scot
By phone: 0131 668 8600
3. Privacy Notice
3.1 We are committed to protecting
your personal data and your privacy. This Privacy Notice sets out the basis on
which we collect any personal data from you, that you provide to us, we acquire
from a third party or will be processed by us.
Please read the following
carefully to understand our practices regarding your personal data and how we
will treat it.
3.2 Before we process your personal
data, we are obliged to inform you who we are, why we need to process your
personal data, what we will do with your personal data, and to whom we will
pass your personal data.
3.3 It is important that the personal
data we hold about you is accurate and current. Please keep us informed if your
personal data changes during your relationship with us.
3.4 This version of our privacy notice
was last updated on 20 June 2024.
4. The data we collect about you
4.1 Personal data or personal
information means any information about an individual from which that person
can be identified. It does not include data where the identity of the
individual has been removed (anonymous data).
4.2 We may collect, use, store, and
transfer different kinds of personal data about you which we have grouped
together as follows:
4.2.1 Identity
Data includes first name, maiden name, last name, username or similar
identifier, marital status, title, date of birth, and gender.
4.2.2 Contact
Data includes billing address, delivery address, email address, and
telephone numbers.
5. How is your personal data collected?
5.1 We use different methods to collect data from you or about you including:
5.1.1 Direct
interactions. You may give us your personal data by filling in forms or by
corresponding with us by post, phone, email or otherwise. This includes
personal data you provide when you:
5.1.1.1 filling in forms on our websites;
5.1.1.2 request marketing to be sent to you;
5.1.1.3 enter a competition, promotion, or survey; or
5.1.1.4 give us some feedback.
5.1.2 Third
parties or publicly available sources. We may receive personal data about
you from various third parties and public sources, for example, Identity and
Contact Data from publicly available sources such as Companies House and the
Electoral Register based inside the EU.
6. How we use your personal data
6.1 We will only use your personal
data when the law allows us to. Most commonly, we will use your personal data
in the following circumstances:
6.1.1 Where it is necessary:
6.1.1.1
for us to carry out a specific task in the public interest that is laid down by
law; or
6.1.1.2
for our legitimate interests (or those of a third party) and your interests and
fundamental rights do not override those interests.
6.1.2 Where we need to comply with a legal or regulatory obligation
6.2 Generally, we do not rely on
consent as a legal basis for processing your personal data other than in
relation to sending third-party direct marketing communications to you via
email or text message.
7. Purposes for which we will use your personal data
7.1 We have set out below, in a table
format, a description of all the ways we plan to use your personal data, and
which of the legal bases we rely on to do so.
7.2 Note that we may process your
personal data for more than one lawful ground depending on the specific purpose
for which we are using your data. Please contact us if you need details about
these specific legal grounds.
Purpose/Activity
|
Type of data
|
Lawful basis for
processing including basis of legitimate interest
|
Where you fill in
forms on websites requesting that we contact you
|
(a) Identity
(b) Contact
|
(a) Necessary for our
legitimate interests (to respond to customer enquiries)
(b) Necessary for us to carry out a specific task in the public interest which is
laid out by law
|
Where you sign up for a newsletter
|
(a) Identity
(b) Contact
(c) Marketing & Communications Data
|
On the basis of your
consent (by signing up for a newsletter you are taking a positive action to
opt-in to receiving marketing material from us)
|
To manage our
relationship with you which will include
(a) Notifying you about changes to our terms or privacy policy
(b) Asking you to leave a review or take a survey
|
(a) Identity
(b) Contact
|
(a) Necessary to
comply with a legal obligation
(b) Necessary for our legitimate interests (to keep our records updated and to
study how customers use our products/services)
|
To administer and protect our business
|
(a) Identity
(b) Contact
|
(a) Necessary for our
legitimate interests (for running our business, provision of administration
and IT services, network security, to prevent fraud and in the context of a
business reorganisation or group restructuring exercise)
(b) Necessary to comply with a legal obligation
|
To use data analytics
to improve our products/services, customer relationships and experiences
|
(a) Usage
|
Necessary for our
legitimate interests (to define types of customers for our products and
services to develop our business
|
8. Disclosures of your personal data
8.1 We may have to share your personal
data with third-party service providers to fulfil our contractual obligations
to you.
8.2 We require all third parties to
respect the security of your personal data and to treat it in accordance with
the law. We do not allow our third-party service providers to use your personal
data for their own purposes and only permit them to process your personal data
for specified purposes and in accordance with our instructions.
9. How long do we retain your data?
9.1 We will only retain your personal
data for as long as necessary to fulfil the purposes we collected it for,
including for the purposes of satisfying any legal, accounting, or reporting
requirements.
9.2 To determine the appropriate
retention period for personal data, we consider the amount, nature, and sensitivity
of the personal data, and the potential risk of harm from unauthorised use or
disclosure of your personal data. We also consider the purposes for which we
process your personal data and whether we can achieve those purposes through
other means, and the applicable legal requirements.
10. Marketing
We will only use your personal data
for direct marketing purposes where you have consented to be contacted for such
purposes. We do not share your personal details with any third party for their
marketing purposes. You have the right to withdraw consent to marketing at any
time by contacting us using the details above or by unsubscribing where there
is an option to do so.
We use trusted third-party media
agencies to help us with our advertising, but we do not share your personal
details with any third party for their marketing purposes. You have the right
to withdraw consent to our marketing at any time by contacting us using the
details above.
If you receive marketing from us on
social media platforms, you are able to withdraw your consent by adjusting your
privacy settings within each social media platform itself. You may see our
adverts if your settings allow for targeted advertising based on attributes of
your social media profile, such as your location, age, and interests. For
example, if you live near one of the historic properties we care for, you may
see an advert (ad) for an event at that specific property.
You may also see our online advertising
as a result of your information being automatically profiled by the social
media platform and your account being selected as part of the audience for the
ad. You can prevent this type of targeting by adjusting your privacy settings within
each social media platform or by adjusting your cookie settings in the browser.
You can also interact with the ad itself and select the options that prevent
further targeted advertising using your information in this way.